Sponsored bug fixes during bug auction at T3BOARD09
On this year's TYPO3 Snowboard Tour in Laax again a bug auction was held in which people could bid for their favourite bugs to be solved. It was a fun event - combined with the task of the attendant developers to actually solve the bugs in question right afterwards.
Read moreTYPO3-SA-2009-015: XSS and SQL injection vulnerabilities in extension "phpMyAdmin" (phpmyadmin)
It has been discovered that the extension phpMyAdmin (phpmyadmin) is vulnerable to XSS and SQL injections.
TYPO3-20081222-3: TYPO3 Security Bulletin
It has been discovered that the extension DR Wiki - Typo3 Wiki extension (dr_wiki) is vulnerable to Cross-Site Scripting (XSS).
TYPO3-20081222-2: TYPO3 Security Bulletin
It has been discovered that the extension WEC Discussion Forum (wec_discussion) is vulnerable to Cross-Site Scripting (XSS) and SQL injection.
TYPO3-20081222-1: TYPO3 Security Bulletin
It has been discovered that the extension phpMyAdmin (phpmyadmin) is vulnerable to SQL injections via XSRF.
TYPO3-20081222-4: TYPO3 Security Bulletin
Several vulnerabilities have been found in the following third party TYPO3 extensions: "Vox populi" (mv_vox_populi), "SB Universal Plugin" (SBuniplug), "Simple File Browser" (simplefilebrowser), "TU-Clausthal ODIN" (tuc_odin), "TU-Clausthal Staff" (tuc_staff), "WEBERkommunal Facilities" (wes_facilities)
UPDATE-ON-RECENT-TYPO3ORG-ISSUE: Update on recent typo3.org issue
IMPORTANT-SECURITY-WARNING: Important security warning
TYPO3-20081113-2: Cross-Site Scripting vulnerability in TYPO3 Core
It has been discovered that the frontend plugin of system extension "felogin" is vulnerable to Cross-Site Scripting (XSS).
TYPO3-20081113-1: Cross-Site Scripting vulnerability in TYPO3 Core
It has been discovered that the backend module "file" is vulnerable to Cross-Site Scripting (XSS).